Privacy policy

Last updated August 2026

Harbor is currently in a private pilot with a small number of translation businesses. This is a real, genuine policy describing exactly how data is handled today, not placeholder text, but it has not yet been reviewed by a lawyer and will be before Harbor is generally available to the public. If anything here is unclear, email us directly, see the bottom of this page.

What this covers

This policy describes how Harbor ("we", "us") handles data belonging to the language service businesses that use our platform (each, a "Tenant"), their staff, their Clients, and the translators ("Vendors") who work with them, when they use Harbor.

What we collect

Account information. Name, email address, and role, collected when someone signs up or is invited to a Tenant. Authentication itself is handled by Clerk, a third-party identity provider, we never see or store a raw password.

Business data. The information a Tenant enters or generates while using Harbor: Client and Vendor records, job details, quotes, invoices, and messages sent through the product.

Uploaded documents. The actual files submitted for translation, and the drafts and edits produced while a job is worked on. These are stored in our object storage provider (Cloudflare R2) and are visible only to the Tenant that owns the job, the Vendor assigned to it, and Harbor staff providing support, never to another Tenant.

Usage data. Ordinary technical logs (timestamps, IP address, browser type) generated by using a web application, used for security and debugging, not for advertising.

How AI is involved, stated plainly

A document submitted for translation is sent to Google's Gemini models to produce an AI-drafted first translation and a confidence score, and, for a Tenant that has enabled Translation Memory, to power search over that Tenant's own past translations. This happens automatically as part of the core product, a human always reviews and approves the final translation before it is delivered. Document content sent to Google for this purpose is processed to generate the response and is not used by Google to train its general-purpose models, consistent with Google's own API terms for this class of service.

Who else sees data, and why

We use a small number of specialist providers to run Harbor, each holding only what they need to do their specific job, never a full copy of everything:

  • Clerk, authentication and account identity.
  • Neon, our database provider, hosted on AWS infrastructure.
  • Cloudflare, object storage for uploaded and translated documents, and DNS.
  • Postmark, transactional email delivery (job confirmations, invites, notifications).
  • Stripe, subscription billing for Tenants, and, where a Tenant enables it, payout account management for Vendors. Stripe never shares raw card details with us.
  • Google (Gemini API), AI-assisted translation drafting and confidence scoring, as described above.
  • HubSpot, only for a Tenant that has explicitly connected it, and only that Tenant's own Client contact and deal data syncs there, under that Tenant's own real HubSpot account, never shared across Tenants.
  • Slack and WhatsApp, only for a Tenant that has explicitly connected them, for notifications and, where enabled, copilot interactions that Tenant has opted into.

We do not sell personal data, and we do not use it for third-party advertising. We do not run marketing or analytics cookies on Harbor today, only the functional session cookies our authentication provider needs to keep someone signed in.

Tenant isolation

Every business record in Harbor belongs to exactly one Tenant, and Harbor's own architecture enforces that no Tenant can see another Tenant's Clients, jobs, documents, or financial data, ever. A Vendor's own identity and reputation are portable across the Tenants they choose to work with, but one Tenant can never see which other Tenants a Vendor works with, or that Vendor's own roster relationship with a competitor.

How long we keep data

Business and job data is kept for as long as a Tenant's account is active, so job history, translation memory, and invoicing records stay available and correct. If a Tenant closes their account, we will delete or anonymize their data within a reasonable period afterward, except where we are required to keep financial records for tax or accounting purposes, or where a genuine legal obligation requires otherwise.

Security

Data is encrypted in transit (HTTPS) and at rest with our infrastructure providers. Sensitive credentials (OAuth tokens for connected integrations, for example) are encrypted before being stored, never kept in plain text. Access to a Tenant's own data within Harbor is scoped to that Tenant's own staff and the Vendors actually assigned to their jobs, and a small, named set of Harbor staff for support and platform operation.

Your rights

You can ask us what personal data we hold about you, ask us to correct it, or ask us to delete your account and associated personal data (subject to the retention exceptions above). Email us using the address at the bottom of this page and we will respond directly, there is no automated self-service flow for this yet during the private pilot.

Children

Harbor is a business tool. It is not directed at, and we do not knowingly collect data from, children.

Changes to this policy

If this policy changes in a way that meaningfully affects how data is handled, we will update the date at the top of this page and, where the change is significant, tell existing Tenants directly, not just quietly update this page.

Contact

Questions about this policy, or a specific piece of data, go to hello@useharborapp.com and a real person will answer directly.